Bug 30772

Summary: python-lxml new security issue CVE-2022-2309
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: QA Team <qa-bugs>
Status: RESOLVED FIXED QA Contact: Sec team <security>
Severity: normal    
Priority: Normal CC: andrewsfarm, davidwhodgins, sysadmin-bugs, yvesbrungard
Version: 8Keywords: advisory, validated_update
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard: MGA8-64-OK
Source RPM: python-lxml-4.7.1-3.mga9.src.rpm CVE:
Status comment:

Description David Walser 2022-08-24 21:34:38 CEST
SUSE has issued an advisory on August 23:
https://lists.suse.com/pipermail/sle-security-updates/2022-August/011973.html

Mageia 8 is also affected.
David Walser 2022-08-24 21:34:52 CEST

Whiteboard: (none) => MGA8TOO

Comment 1 Lewis Smith 2022-08-26 20:28:13 CEST
Assigning to the Python maintainers.

Assignee: bugsquad => python

Comment 2 papoteur 2022-08-27 17:49:20 CEST
In testings:
python3-lxml-4.9.1-1.mga8
python-lxml-docs-4.9.1-1.mga8

Assignee: python => qa-bugs
Version: Cauldron => 8
Whiteboard: MGA8TOO => (none)
CC: (none) => yves.brungard_mageia

Comment 3 Thomas Andrews 2022-09-12 03:43:58 CEST
No installation issues.

Referenced Bug 29817 Comment 4 for testing.

$ strace -o lxmltxt calibre 

Imported an html file from "Grokking the Gimp," downloaded years ago. Converted it to epub format, which I was able to read with the Calibre viewer and with CoolReader3. (Probably not the best format for this document, as the result was 859 pages long in CoolReader3, but it was entirely readable.) There were numerous references in the strace text file to /usr/lib64/python3.8/site-packages/lxml/ files, so OK for me just as it was for Herman.

Validating.

Whiteboard: (none) => MGA8-64-OK
CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

Dave Hodgins 2022-09-16 19:54:14 CEST

CC: (none) => davidwhodgins
Keywords: (none) => advisory

Comment 4 Mageia Robot 2022-09-16 21:41:38 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2022-0331.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED